Usable with caveats: this stable, organization-backed metapackage is clearly licensed, correctly tied to its repository, and has no deprecation or risky workflow findings. Its latest registry release was over four years ago and the repository recorded no commits or active maintainers in the last three months, so future updates are uncertain.
65%
Total Score
75
100
89
83
The package has only four releases and none in the last 12 months; its latest release was published over four years ago. This materially raises maintenance and abandonment concerns, although the package is a stable metapackage with a narrow purpose.
The repository recorded zero commits and zero active maintainers in the last three months. For a small stable metapackage this may reflect low change needs, but it still leaves maintenance responsiveness uncertain.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. This is a transparency gap rather than evidence that the package is unsafe.
The only workflow lacks top-level token permissions, so its permissions are not explicitly constrained at that level. No top-level write permissions were detected, making this a limited workflow-hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-mvc-plugin-prg Version ^1.3 | — | — |
laminas/laminas-mvc-plugin-fileprg Version ^1.2 | — | — |
laminas/laminas-mvc-plugin-identity Version ^1.2 | — | — |
laminas/laminas-mvc-plugin-flashmessenger Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.